docs: add io_uring_* syscalls to seccomp significant syscalls table#24449
Open
docs: add io_uring_* syscalls to seccomp significant syscalls table#24449
Conversation
The io_uring_enter, io_uring_register, and io_uring_setup syscalls were removed from Docker's default seccomp allowlist in moby/moby#46762 due to security vulnerabilities that can be exploited to escape containers. Add them to the significant blocked syscalls table. Fixes #23784
✅ Deploy Preview for docsdocker ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
This PR correctly adds three io_uring_* syscalls to the seccomp blocked syscalls table. The changes are:
- Factually accurate: The syscalls were indeed blocked in moby/moby#46762 for security reasons
- Well-formatted: Entries are alphabetically ordered and consistent with existing table format
- Properly documented: Each entry links to the upstream PR for context
- Style-compliant: No hedge words, meta-commentary, or other style guide violations
The documentation clearly explains why these syscalls are blocked (security vulnerabilities that can lead to container breakout), which helps users understand the security posture.
No issues found. ✅
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
io_uring_enter,io_uring_register, andio_uring_setupto the significant syscalls blocked by Docker's default seccomp profile tableiopl, beforekcmp)Test plan
/engine/security/seccomp/Fixes #23784